9 Commits

4 changed files with 40 additions and 18 deletions

View File

@@ -7,11 +7,11 @@ Install Grafana Alloy from the release binary and configures it to scrape log fi
## Variables
```yaml
alloy_version: "1.17.1"
alloy_config_dir: "/etc/alloy"
alloy_data_dir: "/var/lib/alloy"
alloy_loki_url: "http://localhost:3100/loki/api/v1/push"
alloy_log_paths:
grafana_alloy_version: "1.17.1"
grafana_alloy_config_dir: "/etc/alloy"
grafana_alloy_data_dir: "/var/lib/alloy"
grafana_alloy_loki_url: "http://localhost:3100/loki/api/v1/push"
grafana_alloy_log_paths:
- "/var/log/*.log"
```
@@ -23,8 +23,8 @@ alloy_log_paths:
roles:
- role: grafana_alloy
vars:
alloy_loki_url: "http://loki.example.com:3100/loki/api/v1/push"
alloy_log_paths:
grafana_alloy_loki_url: "http://loki.example.com:3100/loki/api/v1/push"
grafana_alloy_log_paths:
- "/var/log/*.log"
- "/var/log/myapp/*.log"
```

View File

@@ -2,6 +2,7 @@
grafana_alloy_version: "1.17.1"
grafana_alloy_config_dir: "/etc/alloy"
grafana_alloy_data_dir: "/var/lib/alloy"
grafana_alloy_loki_url: "http://localhost:3100/loki/api/v1/push"
grafana_alloy_loki_port: 3100
grafana_alloy_loki_url: "http://localhost:{{ grafana_alloy_loki_port }}/loki/api/v1/push"
grafana_alloy_log_paths:
- "/var/log/*.log"

View File

@@ -4,8 +4,7 @@
name: "alloy"
system: true
shell: "/sbin/nologin"
groups: "adm,systemd-journal"
append: true
groups: "adm"
create_home: false
state: present
@@ -24,13 +23,16 @@
block:
- name: "Install | Check Alloy version"
changed_when: false
failed_when: false
ansible.builtin.command:
cmd: "alloy --version"
register: grafana_alloy_ver
- name: "Install | Assert version correctness"
ansible.builtin.assert:
that: "grafana_alloy_version in grafana_alloy_ver.stdout"
that:
- "grafana_alloy_ver.rc == 0"
- "grafana_alloy_version in grafana_alloy_ver.stdout"
success_msg: "alloy version {{ grafana_alloy_version }} is installed and working"
fail_msg: "alloy version {{ grafana_alloy_version }} is not installed or not working correctly"
@@ -40,10 +42,26 @@
name: "unzip"
state: present
- name: "Install | Fetch and unpack the distribution"
- name: "Install | Download the distribution archive"
ansible.builtin.get_url:
url: "https://github.com/grafana/alloy/releases/download/v{{ grafana_alloy_version }}/alloy-linux-amd64.zip"
dest: "/tmp/alloy-linux-amd64.zip"
group: "alloy"
owner: "alloy"
mode: "0644"
timeout: 30
force: true
register: grafana_alloy_download_status
until: grafana_alloy_download_status is success
retries: 3
delay: 5
- name: "Install | Unpack and delete the distribution"
ansible.builtin.unarchive:
src: "https://github.com/grafana/alloy/releases/download/v{{ grafana_alloy_version }}/alloy-linux-amd64.zip"
src: "/tmp/alloy-linux-amd64.zip"
dest: "/tmp"
group: "alloy"
owner: "alloy"
remote_src: true
- name: "Install | Put the binary under the PATH"
@@ -57,8 +75,11 @@
mode: "0755"
- name: "Install | Clean up the downloads"
loop:
- "/tmp/alloy-linux-amd64"
- "/tmp/alloy-linux-amd64.zip"
ansible.builtin.file:
path: "/tmp/alloy-linux-amd64"
path: "{{ item }}"
state: absent
- name: "Install | Create a systemd service unit"
@@ -66,6 +87,6 @@
ansible.builtin.template:
src: alloy.service.j2
dest: /etc/systemd/system/alloy.service
owner: "alloy"
group: "alloy"
mode: "0660"
owner: "root"
group: "root"
mode: "0600"

View File

@@ -16,7 +16,7 @@ ExecStart=/usr/bin/alloy run {{ grafana_alloy_config_dir }}/config.alloy \
ExecReload=/bin/kill -HUP $MAINPID
# Security hardening
ReadWritePaths={{ grafana_alloy_data_dir }}
ReadWritePaths={{ grafana_alloy_data_dir }} {{ grafana_alloy_config_dir }}
ProtectSystem=strict
NoNewPrivileges=true
PrivateTmp=true